Wednesday, November 4, 2009

What will you do if your computer is suddenly being hacked?

Please tell me the really, very first thing you must do (For laptop? for desktop?)



Pretend that the hacker even gets through your antivirus software.



What will you do if your computer is suddenly being hacked?adware



Laptop and desktop are different.



Laptop:



Immediately power down by forcing it off. Do not shut down normally. That usually takes about 4 seconds. Disconnect the network connection and if on dialup even disconnect the phone. Completely isolate the computer. Tag the computer. Do not restore the power to the computer for any reason. You are now ready to start your forensic investigations.



Desktop:



Yank the power cord. This is slightly faster than forcing it off unless you can't get to the cord. Then force it off with the power switch. Disconnect the network connection and phone line if attached. Tag the computer. Do not restore the power for any reason. You are now ready to start your forensic investigation.



Forensics:



Grab a witness so you have someone who can verify every step you take. Make copies of any firewall logs or other access logs that might contain evidence and tag them. Lock up or leave at least 1 guard to insure that the computers are not tampered with if you can't watch them personally. Buy 2 new hard drives the same size or larger than the one in the attacked computer. Zero the new drives to create a known state. Remove the hard drive from the attacked computer tag it and attach it to another computer with the new hard drive. Make a byte for byte copy of the entire drive including empty tracks and sectors. Make a second copy using the 2nd drive the same as the first. Take the original hard rive out and place it with the other evidence gathered. Tag each of the copy drives and set one aside to use as a restore copy if needed.

No comments:

Post a Comment